VYPR

Simplesamlphp

by Simplesamlphp

Source repositories

CVEs (26)

  • CVE-2017-12867MedAug 29, 2017
    risk 0.31cvss 5.9epss 0.01

    The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.

  • CVE-2020-5226MedJan 24, 2020
    risk 0.29cvss 4.4epss 0.01

    Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be submitted and sent to the system administrator. Starting with SimpleSAMLphp 1.18.0, a new SimpleSAML\Utils\EMail class was introduced to handle sending emails,…

  • CVE-2020-5225MedJan 24, 2020
    risk 0.29cvss 4.4epss 0.01

    Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and sends them via email to the system administrator, did not properly sanitize the report identifier obtained from the request. This allows an attacker, under…

  • CVE-2020-5301LowApr 21, 2020
    risk 0.13cvss 3.0epss 0.01

    SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. The module controller in `SimpleSAML\Module` that processes requests for pages hosted by modules, has code to identify paths ending with `.php` and process those as PHP code. If no other…

  • CVE-2012-0908Jan 24, 2012
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the link_href parameter.

  • CVE-2012-0040Jan 24, 2012
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter.

Page 2 of 2